IP Library Granted Patent US 8,495,716
Granted Patent B1
US 8,495,716 · App. 11/967,473 · Granted Jul 23, 2013

Systems and methods for facilitating online authentication from untrusted computing devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,495,716
App. No.
11/967,473
Granted
Jul 23, 2013
Kind
B1
Abstract

A computer-implemented method for facilitating online authentication from untrusted computing devices may comprise receiving a request to access an online service from a computing device, retrieving authentication information for the online service from a database, accessing the online service using the authentication information for the online service, receiving data from the online service, and transmitting at least a portion of the data received from the online service to the computing device. The method may also comprise converting the authentication information for the online service into non-computer-readable authentication information, such as a human-readable image, and transmitting the non-computer-readable authentication information to the computing device. Corresponding systems and computer-readable media are also disclosed.

Claims (63)

1. A computer-implemented method for facilitating online authentication from untrusted computing devices, at least a portion of the method being performed by a proxy server comprising at least one processor, the method comprising:

receiving, at the proxy server, a request from an untrusted computing device to access an online service;

retrieving, at the proxy server, authentication information for accessing the online service from a database;

using the authentication information to log into the online service at the proxy server without exposing the authentication information to the untrusted computing device;

proxying traffic between the online service and the untrusted computing device at the proxy server without exposing the authentication information to the untrusted computing device by:

retrieving content from the online service at the proxy server;

embedding the content retrieved from the online service at the proxy server within a web page;

transmitting the web page containing the embedded content from the proxy server to the untrusted computing device.

2. The method of claim 1 , further comprising, prior to retrieving the authentication information for accessing the online service, receiving user-account authentication information from the untrusted computing device.

3. The method of claim 2 , wherein the user-account authentication information comprises multi-factor authentication information.

4. The method of claim 1 , wherein retrieving the content from the online service at the proxy server comprises retrieving a web page from the online service at the proxy server.

5. The method of claim 1 , further comprising:

converting, at the proxy server, the authentication information for accessing the online service into a human-readable image; wherein the human-readable image is in a format that enables a user of the untrusted computing device to complete an authentication process required to access the online service but prevents computing devices from extracting useful information;

transmitting the human-readable image from the proxy server to the untrusted computing device.

6. The method of claim 5 , wherein the method further comprises at least one of:

adding visual noise to the human-readable image;

transforming at least a portion of the human-readable image.

7. The method of claim 6 , wherein transforming at least a portion of the human-readable image comprises:

rotating at least a portion of the human-readable image;

stretching at least a portion of the human-readable image;

tilting at least a portion of the human-readable image.

8. The method of claim 1 , further comprising providing a website that allows a user to:

request a human-readable image that is in a format that enables the user to complete an authentication process required to access an online service but prevents computing devices from extracting useful information;

add authentication information for accessing an online service to the database;

edit authentication information for accessing an online service stored in the database;

delete authentication information for accessing an online service from the database;

request access to an online service.

9. The method of claim 1 , wherein the authentication information for accessing the online service is associated with a user account for the online service.

10. A computer-implemented method for securely providing authentication information for accessing online services to untrusted computing devices, at least a portion of the method being performed by a proxy server comprising at least one processor, the method comprising:

receiving, at the proxy server, a request from an untrusted computing device for authentication information for accessing an online service;

identifying, at the proxy server, computer-readable authentication information for accessing the online service;

obtaining, at the proxy server, the computer-readable authentication information for accessing the online service;

converting, at the proxy server, the computer-readable authentication information for accessing the online service into a human-readable image, wherein the human-readable image is in a format that enables a user of the untrusted computing device to complete an authentication process required to access the online service but prevents computing devices from extracting useful information;

transmitting the human-readable image for accessing the online service from the proxy server to the untrusted computing device to enable the user of the untrusted computing device to complete the authentication process required to access the online service.

11. The method of claim 10 , wherein:

identifying the computer-readable authentication information for accessing the online service comprises searching a database for computer-readable authentication information for accessing the online service;

obtaining the computer-readable authentication information for accessing the online service comprises retrieving the computer-readable authentication information for accessing the online service from the database.

12. The method of claim 10 , wherein the method further comprises at least one of:

adding visual noise to the human-readable image;

transforming at least a portion of the human-readable image.

13. The method of claim 10 , wherein transforming at least a portion of the human-readable image comprises:

rotating at least a portion of the human-readable image;

stretching at least a portion of the human-readable image;

tilting at least a portion of the human-readable image.

14. A system for facilitating online authentication from untrusted computing devices, the system comprising:

a database for storing authentication information for accessing an online service;

an access module for:

receiving, at the proxy server, a request from an untrusted computing device to access the online service;

retrieving, at the proxy server, authentication information for accessing the online service from the database;

using the authentication information to log into the online service at the proxy server without exposing the authentication information to the untrusted computing device;

proxying traffic between the online service and the untrusted computing device at the proxy server without exposing the authentication information to the untrusted computing device by:

retrieving content from the online service at the proxy server;

embedding the content retrieved from the online service at the proxy server within a web page;

transmitting the web page containing the embedded content from the proxy server to the untrusted computing device;

at least one processor configured to execute the access module.

15. The system of claim 14 , further comprising a conversion module for converting the authentication information for accessing the online service into a human-readable image that is in a format that enables a user of the untrusted computing device to complete an authentication process required to access the online service but prevents computing devices from extracting useful information.

16. The system of claim 14 , further comprising a website module for providing a website that allows a user to:

request a human-readable image that is in a format that enables the user to complete an authentication process required to access an online service but prevents computing devices from extracting useful information;

add authentication information for accessing an online service to the database;

edit authentication information for accessing an online service stored in the database;

delete authentication information for accessing an online service from the database;

request access to an online service.

17. The system of claim 14 , further comprising a user-authentication module for authenticating a user of the untrusted computing device.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2007
From: NEWSTADT, KEITH; COOLEY, SHAUN
To: SYMANTEC CORPORATION
Reel/Frame 020304/0455 →